Medium severity6.1NVD Advisory· Published May 2, 2022· Updated Jul 9, 2026
CVE-2021-31674
CVE-2021-31674
Description
Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code via undefine enum constant.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
3- tf1t.gitbook.io/mycve/cylos/cyclos-4.14.7-dom-based-cross-site-scripting-in-undefined-enum-cve-2021-31674nvdExploitThird Party Advisory
- www.exploit-db.com/exploits/50908nvdExploitThird Party Advisory
- packetstormsecurity.com/files/167040/Cyclos-4.14.7-Cross-Site-Scripting.htmlnvd
News mentions
0No linked articles in our index yet.